Google's Project Zero wants to protect the internet from evil

[caption id="" align=“alignnone” width=“2500”] Image by Kris Krug under creative commons license [/caption] Google has created a new initiative called Project Zero where it aims to hire superstar hackers and use them to improve intent security. Their goal will be to use their expertise and Google's resources to find security issues with foundational internet technologies. Zero-day back market Newly discovered security issues (bugs, vulnerabilities or anything exploitable) that have not yet been announced are called zero day vulnerabilities. there is a healthy black market buying and selling these vulnerabilities (typical buyers are organized crime, criminals or intelligence agencies).

Continue reading →


Dropcam vulnerable to hackers

Dropcam (Now a Google Nest company) took the remote internet connected video world by storm by allowing anyone to remotely monitor their homes or business' cheaply and without being a technical genius. There are countless media articles about business and homeowners using it to catch thieves, but now we learn that it can be exploited by cybercriminals against you. Two researchers from Synack (Patrick Wardle and Colby Moore) discovered vulnerabilities in Dropcam which they will demonstrate at Defcon 22 in Las Vegas next month.

Continue reading →


TSA requires your gadgets to power on

[caption id="" align=“alignnone” width=“2500”] Image by Martin Abegglen used under Creative Commons License [/caption] The US Transportation Security Administration (TSA) says that users on some in-bound flights originating in certain overseas airports will have to prove [to the security agent] that their devices power on and work as expected. “Powerless devices will not be permitted onboard the aircraft. The traveler may also undergo additional screening.” — TSA The list of where this new rule will be implemented is not yet known so for now, make sure your devices have enough power to switch on and be used.

Continue reading →


IOS from the eyes of a security person

[caption id="" align=“alignnone” width=“2500”] Image by Donald Lee Pardue under Creative Commons License [/caption] When I read Apple's 33 page IOS Security Paper I was blown away (link). Not because its perfect security but it is as close to perfect as it can get in a generally usable commercial product. This unprecedented look inside the Apple security hive mind answered many of my questions and reaffirmed my belief that Apple makes the most secure general use electronics around. At WWDC, I had high hopes and Apple exceeded even my wildest expectations.

Continue reading →


Google wants easy end-to-end email encryption in Chrome

Sending an email is akin to mailing a postcard. Everything written in it can easily be read, copied or analyzed by any one of the email transfer points. It is this simple fact that motivates security advocates to push for email encryption. The main obstacle to mass adoption of email encryption is the complexity. It requires installation and configuration of special software. It requires the purchase or generation of you private/public keys. Google wants to change all of that and has released an alpha Chrome plug-in called End-to-End (link).

Continue reading →


Chinese media demand sanctions against US tech companies

[caption id="" align=“alignnone” width=“2500”] Photo by Rene Mensen under Creative Commons License [/caption] 3 things we know governments will always do are: Tax Spend Spy The last point, fueled by the Ed Snowden leaks, seems to be keeping the media busy. Now the China-run state-owned media is calling on the Chinese government to sanction the major US technology companies who are "pawns of the US Government". China Daily and People's Daily have called upon their leaders to "severely punish" the companies mentioned in the Edward Snowden leaks.

Continue reading →


Hackers bypass Apple's iCloud and Activation lock for iPhone

Apple touts the advanced security features built into its devices and its linked cloud services. One such security feature is Activation Lock that should prevent a thief from using a stolen iPhone that is locked. A Dutch and Moroccan hacker group called "Team DoulCl" are reporting that they have been able to bypass Apple's Activation Lock control. De Telegraaf (link), a Dutch news organization, claims the group was able to buy locked iPhones and unlock them. Thieves can use this hack to resell stolen iPhones for huge profits.

Continue reading →


User claims he can sell 145,312,663 user records stollen from eBay

A user claims that he will sell interested parties 145 312 663 unique records from the eBay hack for only $745US ( 1.453 bitcoins)

Continue reading →


Be vigilant! Don't get scammed online

I hear horror stories everyday about people getting scammed and swindled online by professional thieves. Sometimes you lose a couple of bucks while others lose thousands. Regardless of the amount, it feels bad. Here is an example of an online scam I stumbled on the other day perpetrated on Twitter. <img src="https://ekiledjian2.micro.blog/uploads/2025/93cc47169a.jpg" alt=""> First you get a tweet that looks "normal". They use various subjects that they know people will be interested in. In the above case, both tweets actually take you to the same place.

Continue reading →


Are you being used to attack sites online?

We hear about online attacks almost on a daily basis and the targets are usually (in the media at least) large sites like CNN, Yahoo, Amazon, etc. Did you know that your machine could be an attacker without you even knowing it? How could this happen? Because you most likely have lax security hygiene: easy to guess passwords visit on shady websites load "weird" attachment or more This means your home machine could already be part of a botnet used by bad actors to target companies or organizations with whose view they don't agree with.

Continue reading →